Malvertising Campaign Targets Slack in Google Search Engine
ID: c04f6a15-8a01-536b-8ed5-b7c498b422cb
STIX ID: report--c04f6a15-8a01-536b-8ed5-b7c498b422cb
Feed Name: The Cyber Express
Researchers uncovered a sophisticated malvertising campaign that used fraudulent Google search ads impersonating Slack to funnel victims through layered redirects and cloaked landing pages to a malicious domain (slack-windows-download.com) hosting a download that deployed the SecTopRAT remote access/stealer. The actors employed evasion TTPs — including ad ‘cooking’, click-tracking abuse, and cloaking — to avoid detection, indicating a targeted, active malware distribution effort with potential data-theft impact on affected users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
